Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 185

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
India's KFC, Pizza Hut operators to merge in $934 million deal
Retail investors close out one of their best years ever. How they beat Wall Street at its own game
Trump orders Chinese-controlled firm to unwind chip asset deal, citing national security risks
3 credit card and travel deals that feel too good to last
Bank of America is betting on these stocks, including one Big Tech laggard, in the first quarter of 2026
China’s BYD overtakes Tesla as world’s top EV seller for the first time
Behind the mesh curtain: Why airline class wars will intensify in 2026
Watch Trump's full comments following the U.S. strike against Venezuela
Maduro is out but his top allies still hold power in Venezuela
Maduro overthrow in oil-rich Venezuela unlikely to shake energy markets in the near term